The C variadic spellings ("..." and the GNU "name..."), an empty or
trailing parameter, a missing comma, a stray token and an unterminated
list all parsed silently before: non-identifier tokens were skipped, so
"#define M(...)" defined a zero-parameter macro and invocations were
diagnosed only by argument count, if at all. The toolchain rejects the
definition itself ("bad definition for macro"), and so does the
preprocessor now: the parameter list must be identifiers separated by
single commas and closed by the parenthesis, and a rejected definition
leaves the name unbound. The spellings join the fuzz corpus.
Assisted-by: GLM 5.3
The lexer folds NAME.selector into one identifier, and an object macro
reached through the selector expands with it travelling along, so a
label spelled NAME.selector: restructures exactly like the bare name
would. The macro-name checks now resolve the prefix before the first
period, and the crashing input joins the corpus.
Assisted-by: GLM 5.3
Peeling a stacked label whose name is a macro moves it onto a line of
its own, where its expansion decides the line's shape: an empty body
leaves a bare colon behind, a line the parser rejects. The peel loops
now hold such labels back with the rest of the line, and the crashing
input joins the corpus.
Assisted-by: GLM 5.3
The canonical form splits a label from the instruction that follows it,
but an identifier naming a macro may expand into any token at all: moved
to a line of its own it no longer parses, because the parser accepts a
non-mnemonic first token only behind a label. The names #define'd in
the file now hold such content back, conservatively across the whole
file, and the crashing input joins the corpus.
Assisted-by: GLM 5.3
A label whose name is a macro expands into whatever the body is, so the
line's statement structure exists only after expansion; splitting the
label off changed clean input into a different statement sequence. The
formatter now records the names #define'd above each line and renders
such a label line unsplit, and the crashing input joins the corpus.
Assisted-by: GLM 5.3
An unterminated block comment at the end of a file swallows the
formatter's mandatory final newline, an artifact the token view already
documents as layout; the preproc signature entry now trims it so the
invariant stays about tokens. The triggering input joins the corpus.
Assisted-by: GLM 5.3
A bare GLOBL or DATA parsed without a single diagnostic while leaving a
nil Name in the tree, a pointer every downstream tool dereferences; TEXT
keeps a placeholder beside its error for exactly that reason, and GLOBL
and DATA now do the same. The crashing input enters the corpus.
Assisted-by: GLM 5.3
The two inputs the expansion round-trip target was built for, the object
macro with a parenthesised body and the continuation-only macro body,
enter the seed corpus so every plain go test run replays them.
Assisted-by: GLM 5.3
The one-blank rule before a new block skipped every line that followed a
TEXT directive, not just the function's first label, so a TEXT with an
empty body ran straight into the next declaration. The exemption now
applies to labels only, and the directive shapes around GLOBL and DATA
ranges are pinned.
Assisted-by: GLM 5.3
The include guard's scope is now pinned from three sides: a file
including itself is a cycle diagnostic, a chain of two thousand distinct
headers completes with the deepest content spliced, and a header reached
again through a separate branch splices a second time and is refused as
a redefinition.
Assisted-by: GLM 5.3
Three property tests walk every .s file under the installed GOROOT plus
the repository's kernels: formatting is idempotent and preserves the
token stream, a clean parse keeps its tree through a format pass, and a
cleanly expanding file expands to the same statements afterwards. The
walks skip under -short so the push suite keeps its budget.
Assisted-by: GLM 5.3
A second formatter target holds the assembly path's contract: beyond the
token view, a file the expander reads cleanly must expand to the same
statement sequence after formatting, because the macro language draws
distinctions from layout (the adjacency of a #define name and its '(',
continuation bodies) that a token count cannot see.
Assisted-by: GLM 5.3
The canonical spelling of a #define line glued a '(' to the macro name
whatever the input's spacing, turning an object macro whose body opens
with a parenthesis into a parameterised one, and it flattened the
backslash continuations of a multi-line body into one physical line,
fusing the statements the expansion splits at those boundaries. Both
change what a valid file assembles to, so renderPreproc now keeps the
name's adjacency (the same column check the preprocessor applies) and
restores the continuation boundaries from the token positions.
Assisted-by: GLM 5.3
The RISC-V vector extension and the LoongArch LSX/LASX families carry
no x/arch decode tables, and the loong64 WORD directive is no
instruction: all three stay on the placeholder. The pins record
today's refusal with the corpus rows that assemble the same bytes, so
a decoder bump that learns one of these spaces flips a row here and
asks for the naming pass to cover it.
Assisted-by: GLM 5.3
x/arch's Plan 9 renderer decodes thirty-odd scalar loong64 operations
perfectly but prints them as "Unknown OP args", and names the
sign-extension pair EXT.W.B/EXT.W.H "?". The supplementary naming
pass re-renders them with the toolchain's own spellings: the families
whose operand order x/arch already prints the Plan 9 way trade only
the mnemonic, and the pointer loads and stores, the acquire loads,
the release stores, PRELD and ALSL are rebuilt from the decoded
arguments with the toolchain's operand order and its raw displacement
reading. ADDU16I.D, a macro helper the assembler never takes as
input, keeps the decoder's Unknown render.
The loong64 parity fixture grows from 73 to 385 rows, pinning every
unique four-byte corpus word the decoder accepts, and the LL/SC
displacement divergence in the encoder is documented for asm.
Assisted-by: GLM 5.3
arm64asm rejects three exception-space words the toolchain's corpus
assembles: the hypervisor call HVC, the secure monitor call SMC and
the speculation barrier SB. The supplementary naming table reads
the raw word in the error branch and renders the corpus spellings;
the corpus rows are pinned in the parity fixture and the boundary
test holds the unallocated neighbours on the placeholder.
Assisted-by: GLM 5.3
The names naming_amd64.go and naming_amd64_test.go carried the _amd64
filename suffix, which the go tool reads as an implicit GOARCH=amd64
build constraint: the tables disappeared from every non-amd64 build
and the package failed to compile for arm64, riscv64 and loong64, the
other three architectures the tool assembles. Renaming to
amd64_naming.go removes the constraint; the module builds again for
all four GOARCH values.
Assisted-by: GLM 5.3
The toolchain's assembler corpus carries 195 amd64 encodings the
x/arch decoder rejects or degenerates: the BMI1/BMI2 VEX families
(ANDN, BEXTR, BLSI, BLSMSK, BLSR, BZHI, MULX, PDEP, PEXT, RORX,
SARX, SHLX, SHRX), the 0F 01 quartet CLAC, STAC, RDPKRU and WRPKRU,
the bare and REX-only RDSEED forms, and UD1. The supplementary
naming table decodes the VEX prefix and the ModR/M shape and renders
the toolchain's own spellings; every corpus row is pinned in the
unlisted fixture and round-trips byte for byte through the encoder,
and the boundary test pins the prefix shapes no family carries.
Assisted-by: GLM 5.3
The operand-width reconciliation closes the byte-register fixture lines
byte for byte: XADDL, XCHGL, CMPXCHGL and CRC32 with byte registers, the
ALU and TEST immediates against AL and DL, and the unlisted accumulator
short forms. MOVL $0x7, DL stays mapped for the legal-encoding choice
alone: the toolchain's own table says "c6c207 or b207", go tool asm emits
b207, and the fixed-point invariant holds with it.
Assisted-by: GLM 5.3
Table-driven rows for the renderer's spellings (the L suffix or none with
a byte register encodes the byte form, every register joining at its low
byte), the refusals (W, Q and the MOVD alias take no byte register) and a
differential kernel of the B-suffixed spellings assembled through both
gasm and go tool asm, byte for byte.
Assisted-by: GLM 5.3
The suffixed scalar families derived the operand width from the mnemonic
alone, so a byte-spelled register under the L spelling or no suffix at all
encoded the widened form: XADDL DL, DL emitted 0F C1 where the byte form is
0F C0, CMPL AL, $7 emitted the 32-bit immediate form where the AL form is
3C 07, and CRC32 DL, R11 widened past the F0 byte opcode. operandWidth now
reconciles the suffix with the operands: a byte register (AL, DL, R8B, ...)
forces the 8-bit form, which is the text the toolchain's own disassembly
prints for those encodings, while the W and Q spellings never ride a byte
register and are refused as go tool asm refuses them (MOVQ AL, AX). The
shift count and the two- and three-operand IMUL forms stay out of the
reconciliation, and the byte accumulator short forms now belong to the AL
spelling alone, matching the toolchain's division (ADDB $3, AX is
80 c0 03, TESTB $7, AX is f6 c0 07).
Assisted-by: GLM 5.3
The launch-failure audit raced the clock: it asserted the dead debuggee
surfaced within 1.5 seconds, a bound the loaded machine behind a ten-way
test storm regularly starved past even though the poll detects the dead
notice within milliseconds of its appearance. The audit now proves the
property itself: a stub debuggee that starts in single-digit milliseconds
marks itself dead, so the notice is always inside the poll's budget and
the error must come from the dead-file watch, while the real binary is
checked without any wall-clock bound. A companion audit drives Kill
through a parked, a doubly killed and a run-to-exit session, the states
whose cleanup used to hang the package, under a watchdog.
Assisted-by: GLM 5.3
The Go runtime can migrate the debuggee's target-mode goroutine off the
process leader before PTRACE_TRACEME, which left the trace relation on a
thread the session never addressed: its stops starved the waits on the
leader, and a kill sequence that resumed nothing and then blocked in
Wait4 hung the whole package. The debuggee now reports the traced thread
in the launch handshake and parks with a thread-directed stop, every
ptrace request and wait addresses that thread, a SIGURG arriving on a
single-step resumes it as a single-step again instead of letting the
tracee run uncontrolled, a resume rejected with ESRCH lifts a group-stop
with SIGCONT and retries once, and Kill resumes, kills and reaps through
non-blocking waits so it returns for a tracee in any state.
Assisted-by: GLM 5.3
The CASALH entry carried the CASB/CASH opcode pattern where the acquire
forms take the full fixed field, so the word differed from the
toolchain's in one opcode bit. Pinned against the oracle word.
Assisted-by: GLM 5.3 Flash
Offsets beyond the split bands ride a per-function literal pool the way
the toolchain lays one out: a PC-relative literal load into REGTMP, then
the register-offset access (the pair family adds the base addition), the
pooled words appended after the last instruction behind the UNDEF guard,
deduplicated by value with the sign- and width-aware load selection.
The same differential pass against the corpus exposed three wrong-code
bugs and fixes them: the logical-immediate period marker rode the wrong
position for every element below 64 bits, so the 32-bit forms encoded a
different constant than written; the plain register operand of an
ADD/SUB against SP took the shifted-register form where the toolchain
uses the extended one with the identity extend, silently truncating
through UXTB; and the AUTIA1716 and AUTIB1716 hint constants were the
PACIA and PACIB encodings. An offset sweep across every band boundary
now pins all three against the live oracle.
Assisted-by: GLM 5.3 Flash
Offsets the single-instruction forms cannot carry lower the way the
toolchain lowers them: ADD or SUB moves the whole distance into REGTMP
within the ±4095 band, and the 24-bit band above it splits into an ADD of
the high half and an access of the low half, with the pair family taking
the two-ADD sequence. The split band follows loadStoreClass per width,
byte accesses taking the full 24 bits and the Q width the widest, so an
offset the toolchain pools is never split instead.
Assisted-by: GLM 5.3 Flash
The pair encoder derived the imm7 divisor from the width suffix alone, so
the 128-bit FP pairs divided their offsets by eight and encoded twice the
distance. The Q spellings scale by sixteen like every other 128-bit
access; the differential kernel carries them now.
Assisted-by: GLM 5.3 Flash
FMOVQ routes through the MOV load/store machinery in the plain, post-index,
pre-index and static-symbol forms. The Q width carries its size in the opc
field, so the store spelling is opc=10 and the access scales by sixteen;
both come from helpers now instead of the size exponent. The static-symbol
form takes the toolchain's twelve-byte ADRP + ADD + access fallback with the
R_ADDRARM64 pair. The register-to-register and immediate forms stay
rejected, matching the toolchain's own table.
Assisted-by: GLM 5.3 Flash